VulnerabilityModified
CVE-2016-0397
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
MEDIUM 5.9EPSS 1.12%
Does this matter?
Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.
Description
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/bigfix webreports
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21985907Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/92467
- http://www-01.ibm.com/support/docview.wss?uid=swg21985907Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/92467
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.